Resource Exhaustion Vulnerability in MongoDB Server by MongoDB Inc.
CVE-2026-13069
7.1HIGH
What is CVE-2026-13069?
An authenticated user can exploit a vulnerability in MongoDB Server by submitting a specially crafted Queryable Encryption find payload. This payload contains an unvalidated field that manipulates internal processing loops. The exploitation of this vulnerability results in excessive CPU usage and can lead to out-of-memory conditions, adversely affecting the availability of the database for legitimate operations. This can cause significant disruptions in service, impacting overall performance and accessibility for other users.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12